BIND 9 DoS Flaw Prompts Patch Advisory
IPA warns of a denial-of-service vulnerability in ISC BIND 9 that could crash DNS servers, urging admins to upgrade to fixed versions.
The Information-technology Promotion Agency (IPA) of Japan issued an advisory regarding a denial-of-service vulnerability, CVE-2025-40775, affecting ISC BIND 9 DNS server software. If exploited, a remote attacker could cause the affected product to terminate abnormally, disrupting DNS resolution services.
No active exploitation has been observed at the time of publication, but the IPA cautions that attacks could emerge in the future and recommends that DNS server administrators apply patches promptly. ISC has released fixed versions BIND 9.20.9 and BIND 9.21.8 to address the flaw; versions prior to 9.18.0 were not evaluated for this vulnerability.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250523.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free